Key wrapping system and method using encryption
A method for enabling secure communication between a first node in a distributed network and at least one second node in the distributed network by using a cryptographic key, including the steps of using an encrypting key to encrypt the cryptographic key to generate a wrap key in a secure hardware module, transmitting the wrap key to the at least one second node over a network, and decrypting the wrap key using the encrypting key to obtain the cryptographic key. Also, a system for enabling secure communication in a distributed network by using a cryptographic key, including a first node transmitting the cryptographic key, a secure hardware module for encrypting the cryptographic key with a encrypting key to obtain a wrap key, a network for transmitting the wrap key, and a second node, the second node configured to decrypt the wrap key using the encrypting key to obtain the cryptographic key.
1 . A method for enabling secure communication between a first node in a distributed network and at least one second node in the distributed network by using a cryptographic key, the method comprising the steps of:
a. Using an encrypting key to encrypt the cryptographic key to generate a wrap key in a secure hardware module;
b. Transmitting the wrap key to the at least one second node over a network; and
c. Decrypting the wrap key using the encrypting key to obtain the cryptographic key.
2 . The method of claim 1 , wherein the cryptographic key is generated by the secure hardware module.
3 . The method of claim 1 , wherein the first node is key authority point.
4 . The method of claim 1 , wherein the encrypting key is a pre-shared key.
5 . The method of claim 1 , wherein the second node is a policy enforcement point.
6 . The method of claim 5 , wherein the cryptographic key is used to negotiate a secure connection between the policy enforcement point and a second policy enforcement point.
7 . The method of claim 6 , wherein the negotiation is based on the Internet Key Exchange (IKE) protocol.
8 . The method of claim 1 , further comprising the step of storing the cryptographic key in the secure hardware module.
9 . The method of claim 8 , further comprising the step of disabling the secure hardware module if it is tampered.
10 . A system for enabling secure communication in a distributed network by using a cryptographic key, the system comprising:
a. a first node transmitting the cryptographic key;
b. a secure hardware module for encrypting the cryptographic key with a encrypting key to obtain a wrap key;
c. a network for transmitting the wrap key; and
d. a second node, the second node configured to decrypt the wrap key using the encrypting key to obtain the cryptographic key.
11 . The system of claim 10 , wherein the encrypting key is a pre-shared private key.
12 . The system of claim 10 , wherein the secure hardware module generates the cryptographic key.
13 . The system of claim 10 , wherein the first node is a key authority point.
14 . The system of claim 10 , wherein the second node is a policy enforcement point.
15 . The system of claim 14 , further comprising at least another policy enforcement point.
16 . The system of claim 10 , wherein the cryptographic key enables Internet Key Exchange (IKE) protocol based negotiation between the first node and the second node.
17 . The system of claim 10 , wherein the secure hardware module stores the cryptographic key.
18 . The system of claim 10 , wherein the secure hardware module is disabled when tampered.
19 . A secure hardware module for enabling secure communication in a distributed network using a cryptographic key, the secure hardware module comprising:
a. a cryptographic key generation module for generating a cryptographic key;
b. a wrap key generation module for encrypting the cryptographic key with a encrypting key to obtain a wrap key;
c. a storage module for storing the cryptographic key; and
d. a key protection module for protecting the cryptographic key from being accessed and for disabling the secure hardware module when tampered.
20 . The secure hardware module of claim 19 , wherein the secure hardware module generates the wrap key for a key authority point.
21 . The secure hardware module of claim 19 , wherein the wrap key is transmitted to at least one policy enforcement point.
22 . The secure hardware module of claim 19 , wherein the encrypting key is a pre-shared private key.